3.0.0
7 years ago
1 years ago
Known vulnerabilities in the in-toto package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
in-toto is a framework to define and secure the integrity of software supply chains Affected versions of this package are vulnerable to External Control of System or Configuration Setting. The in-toto configuration is read from various directories and allows users to configure the behavior of the framework. The files are from directories following the XDG base directory specification. Among the files read is How to fix External Control of System or Configuration Setting? Upgrade | [,2.0.0) |